[UPDATE] [hoch] n8n: Mehrere Schwachstellen
Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in n8n ausnutzen, um beliebigen Programmcode auszuführen, Sicherheitsmaßnahmen zu umgehen, serverseitige Request-Forgery-Angriffe (SSRF) durchzuführen, Informationen offenzulegen und Daten zu manipulieren.
CSIRTS triage
- What
- Multiple vulnerabilities in n8n allow authenticated attackers to execute arbitrary code, bypass security measures, perform SSRF attacks, disclose information, and manipulate data.
- Who is affected
- n8n deployments accessible to authenticated users are affected.
- Urgency
- High severity; remote code execution by authenticated users is critical.
- Action
- Patch n8n to the latest security release immediately.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch n8n
Get an email when a new n8n advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2936
Recent advisories for n8n
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- unknownn8n security advisory (AV26-916)cccs · 2026-09-11
- mediumGHSA-cw9w-vv67-hf73: n8n: Per-Resource OAuth Consent Bypass via Unbound Refresh Token Resource Substitutionghsa · 2026-09-10
- mediumGHSA-q5wm-mgqx-fv2f: n8n: Instance AI Credential Setup Accepts Unvalidated Probe URL from Fetched Contentghsa · 2026-09-10
- mediumGHSA-qgpw-8g46-w95v: n8n: Git Node branch. .remote Config Key Bypasses Sandbox Path Restriction, Enabling Loca…ghsa · 2026-09-10
- mediumGHSA-cqr2-h44g-v75v: n8n: Cross-Tenant Project-Member PII Disclosure via Missing Per-Project Scope Check on Ro…ghsa · 2026-09-10
- mediumGHSA-pq6c-vh67-xpm3: n8n: Log Streaming Event Destinations Decrypt Generic-Auth Credentials Without Ownership …ghsa · 2026-09-10
More from CERT-Bund (BSI) Security Advisories
- medium[NEU] [mittel] Microsoft Edge: Schwachstelle ermöglicht Cross-Site Scripting2026-09-14
- medium[NEU] [mittel] Citrix Systems Workspace App Windows: Mehrere Schwachstellen ermöglichen nicht spezifizierten A…2026-09-14
- medium[NEU] [mittel] wpa_supplicant: Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen2026-09-14
- medium[NEU] [mittel] WP Royal Royal Elementor Addons: Schwachstelle ermöglicht Offenlegung von Informationen2026-09-14
- low[UPDATE] [niedrig] 7-Zip: Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen2026-09-14